CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Improper Restriction of XML External Entity Reference in PlonePlone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). CWE-611Dec 30, 2020 | CVSS-v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
SSRF attacks via tracebacks in PlonePlone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). CWE-918Dec 30, 2020 | CVSS-v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper Restriction of XML External Entity Reference in PlonePlone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. CWE-611Dec 30, 2020 | CVSS-v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |